Developer tools and infrastructure
Security scanners for AI-built apps
Tools that scan websites, GitHub repos, and codebases for exposed secrets, missing headers, open database rules, and other vulnerabilities, mostly aimed at people shipping vibe-coded apps, with a tail of AI pentesting agents, phishing checkers, and other security utilities.
Built for: Indie founders and vibe coders
Projects since May 04
253
Different builders
244
Last 4 weeks vs 8 before
-1%
AI is the core
17%
Projects per week
Mostly web app (42%), developer tool or library (34%), other (4.0%) · from r/SideProject, r/vibecoding, r/SaaS, r/chrome_extensions
Latest
- Client report kit — Generates local HTML reports from checks already performed, separating confirmed issues, passed checks, hypotheses and unverified items.“A local reporting kit for web agencies: form confirmation is not proof of delivery”
- CyberGuard AI — Flags phishing emails and suspicious URLs in real time by combining email text, sender and domain signals, embedded links and security headers.“CyberGuard AI: Context-aware phishing detection using email, URL, sender and security signals”
- Scans npm lockfile dependencies for malicious install scripts, exfiltration code, and obfuscation using an AI reviewer.“crypto dev, paranoid about my keys leaking, so I built a dependency scanner”
- Klarion — Scans code for leaked secrets using regex and entropy checks, then has an AI model judge whether each flagged match is real.“Worried about your AI agent leaking secrets, or tired of secret-scanner false positives?”
- BreakYourApp — Scans web applications for issues and generates a bug report using an AI QA agent.“I built an AI QA agent that tries to break your web app”
- Scam Sentinel — Scores whether an email or message is a scam, including reading text inside inline images.“I tested my scam detector against ~1,800 scams. The one that beat it was a screenshot.”
- Fomatix Sensitive Data Masker — Detects and replaces sensitive values like emails, IPs, IDs and tokens in logs and JSON while keeping their structure, entirely in the browser.“We built a browser-local tool to sanitize large logs & JSON before sharing them with AI or support”
- MACSPLOIT — Provides an open-source macOS security workbench for automated penetration testing and bug bounty work, with a planned node interface for AI models that can run hacking tasks.“I’m building an open-source macOS security workbench; looking for feedback.”
- Security questionnaire response kit — Provides a manual document and workbook kit for organizing answers, evidence, exceptions, and approvals for customer security questionnaires.“I made a manual security-questionnaire response kit for small B2B SaaS teams”
- Kurokagi — Scans APIs for authorization flaws such as IDOR, BOLA and BFLA by testing whether one identity can access or modify another's resources.“Built an open-source API authorization scanner in Go”
- ResilAI — Checks a clinic's backups, logs, and security controls each morning and reports whether it is safe to see patients, with the single most important fix if not.“I built a morning check that tells a small clinic if it's actually safe to see patients today”
- CheckExploit — Runs real exploits against a project's code in an isolated sandbox to show which dependency vulnerabilities actually reach the code.“Built an AI agent to check exploitability of your code”
- Shrine — Scans code repositories for exposed secrets, leaked JWTs, and Supabase misconfigurations from the command line.“I made a scanner. It found a leak in the scanner.”
- Cylist — Combines IOC lookups across threat-intel services, security news, case generation and community discussion into one workspace for SOC analysts.“Built a free all-in-one platform for SOC analysts — now looking for beta testers & honest feedback”
- Runs quick security and site health checks on a vibe-coded web app from its URL and emails a report of issues to fix.“I built a production readiness scanner”
- CipherLens — Analyzes unknown input data in the browser and ranks which encoding, cipher, or compression operation most likely produced it.“I built CipherLens — a local-first tool that tries to identify what operation could explain unknown data”
- PreflightX — Checks publicly accessible parts of a web app for exposed secrets, missing security headers and sensitive files.“I scanned 100 AI-built apps for security issues. Here’s what I found.”
- Click Scout — Checks a link or email sender when hovered and reports whether it appears safe.“I got tired of users clicking on stupid links so I built this chrome extension”
- MAGI — Provides a security-focused web service, with specifics not described in the post.“Made my first revenue project, fingers crossed”
- myrecon — Searches usernames across many websites and runs email breach, IP and domain lookups.“My side project just made ₹0.00 in revenue 30 days after launch... this feels so real! 🎉🎉🎉”
Most discussed
- Runs a SaaS app that requires email verification at signup, which bots have been getting past.“Bots attacking my SaaS App”
- try.glass — Scans vibe-coded apps for exposed API keys, open .env files, and unauthenticated API endpoints.“What are you building this week? Drop your project”
- Vibe-coded app security scanner — Scans public GitHub repos of AI-built apps for security vulnerabilities and reports the findings.“Scanned 48 vibe coded apps. Results worse than expected”
- Scans vibe-coded web apps for common security flaws and returns a fix prompt to paste into an AI builder.“I audited 8 vibe-coded apps last week. 8 out of 8 had a high-severity hole, and they were almost identical”
- CodeCrash — Simulates attacker attempts against submitted code and explains exploits and fixes for issues like SQL injection and XSS.“I built an AI that simulates how hackers would break your code before production — looking for feedback from devs”
- BasinCheck — Runs safety audits for oil and gas contractor teams as a B2B software tool.“Crossed $1.2k MRR with 2 customers. The “underrated growth tactic” was obsessing over customer #1.”
- Should I Ship — Scans a code repository for common pre-launch problems such as missing auth checks, unverified Stripe webhooks, exposed keys, and missing rate limits, then gives a readiness score and suggested fixes.“Your AI-built app works. That doesn’t mean it’s safe to launch.”
- AI App Production Readiness Scorecard — Scores an app's launch readiness from a checklist of hardening items and lists the highest-priority fixes.“I run a dev shop that fixes AI-built apps for launch here’s the same 4 things that are broken almost every time (+ a free scorecard)”
- Secuum — Runs over 300 security tests against a public website or app to check for issues like missing HTTP headers and exposed API or payment keys.“Vibecoded a security testing solution for vibecoders”
- Teaches common web security flaws through a hands-on capture-the-flag challenge set.“Vibe coders without a security background how are you handling security?”